Policy changed — see what exactly · 2026-08-18 →
German Federal Office of Administration. 58 requests, 1 domain. GSB platform, Apache. BundesSchrift (BundesSans + BundesSerif) served locally. A proprietary GSB cookie banner, only technically necessary cookies (§25(2)(2) TDDDG). The CSP reserves piwik.itzbund.de, YouTube, googleapis, geodatenzentrum — inactive in the HAR. Set-Cookie — zero. Full compliance.
Timeline of the leak
Declared versus actual
Context
BVA (Bundesverwaltungsamt) is a general-purpose federal service agency, carrying out around 150 tasks on behalf of other federal bodies: from BAföG and Kindergeld payments to registry management and visa support. Germany’s largest service agency. GSB platform, Apache. HAR: 58 requests, 1 domain.
BundesSchrift — five weights, local
BVA uses BundesSansWeb (Regular, Bold, BoldItalic, Italic) and BundesSerifWeb-Bold — five woff files from /static/fonts/BundesSchrift/. The state font family, hosted locally. slick.woff for the slider — also local.
A proprietary cookie banner — only necessary cookies
The cookie banner is implemented with GSB’s own tools, with no external CMP. The policy lists only technically necessary cookies: JSESSIONID (session), SERVERID (load balancing, expires with the session), and the banner’s cookie (closed, signaling it was dismissed). All under §25(2)(2) TDDDG, with no consent required. Set-Cookie — zero in the HAR.
The CSP as a map of capabilities, not current state
The Content-Security-Policy reserves a wide range of external sources for features on internal pages: piwik.itzbund.de (Matomo after consent), *.googleapis.com and *.youtube.com (YouTube videos), *.geodatenzentrum.de (BKG maps), service-digitale-verwaltung.de (OZG services). Not one of these sources is active on the homepage — there are no requests outside www.bva.bund.de in the HAR.
Policy — detailed and current
The privacy policy, roughly 47,000 characters long, covers all the services mentioned in the CSP: Matomo only after consent, YouTube with a warning about user responsibility, BKG geodatenzentrum.de, the OZG platform, BVA’s social media. Cookies are described in a table listing name, purpose, and category. Legal references are current: TDDDG §25 is cited correctly.
Conclusion
www.bva.bund.de does not transmit visitor data to third parties on first visit. One domain, a state typeface, a GSB cookie banner, a detailed policy with current legal references. No GDPR violations recorded at the time of the audit.
ed99a04583732276a988cb5af3c5065f0e15e43cd9e24de9d0f610ea18214e7f